
ZyXEL Confidential
404XD3C0.docx
141/181
(3) Edit web eWC/VPN, add gateway policy, Name=IKE2, Remote Gateway
Address=0.0.0.0, Pre-Shared Key=12345678, Enable Extended
Authentication=enable, Client Mode/User Name=dut1, Client
Mode/Password=dut1
(4) Edit web eWC/VPN,add gateway policy, Name=IKE3, Remote Gateway
Address=0.0.0.0, Pre-Shared Key=12345678, Enable Extended
Authentication=enable, Server Mode=enable
(5) Edit web eWC/VPN, add network policy for IKE1, Active=enable,
Name=IPSec1, Local Network/Starting IP Address=192.168.2.43, Remote
Network/Starting IP Address=192.168.1.33
(6) Edit web eWC/VPN,add network policy for IKE2, Active=enable,
Name=IPSec2, Local Network/Starting IP Address=192.168.2.53
(7) Edit web eWC/VPN,add network policy for IKE3, Active=enable,
Name=IPSec3, Local Network/Starting IP Address=192.168.2.33
5. [BUG FIX]
Symptom: In eWC->Wireless, When select WPA or WPA PSK, the Authentication
Databases field always says: Local User first then RADIUS.
Condition: Go to eWC>WLAN>Wireless, when select WPA or WPA PSK,
the Authentication Databases field always says: "Local User first then RADIUS".
But it shouldn't.
(1) When selecting "WPA", we should show "Authentication Database = RADIUS"
instead of "Authentication Databases Local User first then RADIUS"
(2) When selecting "WPA+PSK", "Authentication Databases" should be hidden.
Modifications in V3.64(XD.0)b3 | 02/03/2005
1. [BUG FIX]
Symptom: OpenPhone H.323 traffic will be blocked by Firewall if connection is
initiated from WAN side to LAN side.
Condition:
PC1(OpenPhone)--------(LAN) ZyWALL (WAN) --------- PC2(OpenPhone)
192.168.1.33
(1) Enable Firewall, setup a WAN2LAN firewall rule for H.323 service
(2) Enable NAT port forwarding for port 1720(H.323) to PC 192.168.1.33
(3) Enable H.323 ALG by "ip alg enable ALG_H323"
(4) PC1 and PC2 use OpenPhone, PC2 call PC1.
(5) OpenPhone application traffic will be blocked by Firewall, you will see a lot of
Firewall blocked log in Centralized LOG.
2. [BUG FIX]
Symptom: DPD vendor ID is not correct.
Condition: VID value of DPD is not compatible with RFC3706.
3. [FEATURE CHANGE]
WAS: The second datagram will use the last 8 octets of the first datagram as IV. This
may cause IV "predictable".
IS: All datagrams will use random IV to make IV unpredictable.
Comentarios a estos manuales